Slashdot videos: Now with more Slashdot!

View

Discuss

Share

We've improved Slashdot's video section; now you can view our video interviews, product close-ups and site visits with all the usual Slashdot options to comment, share, etc. No more walled garden! It's a work in progress -- we hope you'll check it out (Learn more about the recent updates).

An anonymous reader writes with a story about Wang Jianwei, a grad student in China who recently released a paper detailing a vulnerability in the US power grid. Despite the paper being rather typical for security research, its origin set off alarm bells for military strategist Larry M. Wortzel, who testified before Congress that the student was a threat, despite the fact that the published attack wasn't really feasible. Quoting:
"'We usually say "attack" so you can see what would happen,' [Wang] said. 'My emphasis is on how you can protect this. My goal is to find a solution to make the network safer and better protected.' And independent American scientists who read his paper said it was true: Mr. Wang's work was a conventional technical exercise that in no way could be used to take down a power grid. The difference between Mr. Wang's explanation and Mr. Wortzel’s conclusion is of more than academic interest. It shows that in an atmosphere already charged with hostility between the United States and China over cybersecurity issues, including large-scale attacks on computer networks, even a misunderstanding has the potential to escalate tension and set off an overreaction. 'Already people are interpreting this as demonstrating some kind of interest that China would have in disrupting the US power grid,' said Nart Villeneuve, a researcher with the SecDev Group, an Ottawa-based cybersecurity research and consulting group."

The biggest mistake he made in his paper was the assumption that Homer still works at Springfield Nuclear Power Plant. Clearly China is several seasons behind in their 'research'.

The biggest mistake we made was that we actually still have Montgomery Burns running our power plants, and people like him running our national infrastructure. Which was this guy's point: There is in fact a systemic flaw in capitalism -- adding security decreases profitability, therefore security is rarely focused on even in applications that are critical to a country's well-being. The soviets published a report in the mid 80s detailing key areas in our national infastructure that lack redundant power pathways. If about 5% of our infrastructure were destroyed in key areas, about 45% of the grid would be inoperable.

since you guys beat the Russians financially I think that is debatable.

We didn't beat them financially. They imploded with a coup de etat. It was an internal affair that the US intelligence community later took credit for orchestrating. Which is part bullshit because if it hadn't have had the support of people within the former Soviet Union to begin with, it never would have succeeded. And I question that we "beat them financially" -- because we've lost in a lot of other areas. International opinion of our country, social services, and other domestic areas. There are large tra

Huh? The only successful coup d'etat was in 1993 (when there was no USSR anymore), when Yeltsin dissolved the commie parliament. The one before it in 1991 was hardline commies trying to oust Gorbachev, and it wasn't successful.

Regardless of which one you're referring to, the country was gutted long before either one of them.

You go back in time and tell that to the political prisoners in the gulags. Russia was hell under communism. Why was there corruption? Because the system didn't work at all. Now, as a Swede I can firmly give a reasoned and experienced backing of extensive socialist policies apparently considered "extreme" in the US, but don't confuse that for "communism".

While I don't know about "financially" (since the USSR didn't organize its finances in an easily comparable way) it's reasonably clear that it was economically where the USA and its allies were ahead of the USSR (and their allies). In particular, the west was able to sustain a higher level of military spending without crippling the rest of its economy.

Of course, we only really knew how bad things had got through the '70s and early '80s quite a bit later, and that wasn't a period when the Maniacs of Wall Str

Yes, it would've been much better for this guy not to publish his research so we wouldn't know about this problem and leave it wide open. We should be thanking this man for his hard work, not lambasting him just because he happens to be Chinese.

If the Chinese government were interested in disrupting our power systems, wouldn't they be a little more secretive about their intentions than shouting out our flaws to all the world?

Mr. Wang’s work was a conventional technical exercise that in no way could be used to take down a power grid.

no practical scenarios of an attack on the real power grid can be derived from such work.

It doesn't sound like there is a problem per say, having not read his actual work, but it looks like he simply based his theoretical problem in the US because the base data set was the best maintained and he speaks English.

Maybe the Chinese universities would be happy to take him, let him do his research and publish his stuff.

I understand that you didn't read the article, no one ever does, but to not read the summary? He's a Chinese Grad student at a Chinese university. They already let him do his research and publish his findings. The reason he didn't do it on China's grid is that they wont provide him with any data.

I believe that outlaw radio signals are a lot easier to trace than outlaw TCP/IP. Your ARRL would be ecstatic over the opportunity to find and shut down illegal radio transmissions - that can affect WiFi too.

The problem is confirmation bias. The U.S. has been concerned that the Chinese are going to threaten U.S. security by using computers. When the U.S. found a paper written by a Chinese researcher that talked about using computers to attack the U.S. power system, they thought they found someone who was threatening U.S. security. In other words, when they found "evidence" that looked on the surface that it was what they were looking for, they jumped to the conclusion they had found it.

This is just the same as the "quote mining" we've seen from, say, intelligent design supporters who are continually on the lookout for evidence that evolution is wrong. It's also the reason that the hacked CLU emails are being misinterpreted to mean that AGW is a hoax. If you set out looking for evidence to support your idea, you need to make sure you also look for evidence that supports the opposite of your idea, and make sure you are interpreting the evidence you find correctly and neutrally.

Yes, of course if you cherrypick only scientific studies that agree with what you want to believe, yes, you can prove nearly anything you like. This is because even if the study has been designed properly, has been carried out properly, and the results have been analyzed properly, about 5% of the time the conclusion will be incorrect. You can nearly always find a study that shows or a scientist who asserts whatever you care to believe. You need to look at all the available evidence, including evidence that

It is confirmation bias for the mass and politicians, but FUD marketing for the security/defense industry. Indeed, without FUD, most defense contractors around the world would have been out of works decades ago.

In mass media, we call it sensationalism. Newspapers, magazines, and TV reporters present people who proselytize the most extreme viewpoints as evidence of a controversy about this and a controversy about that, even where no such "controversy" exists. They aren't making up that there are people having an argument, but they go out of their way to cherrypick the extremists that are at the opposite extreme ends of any issue. Have you noticed all the reports about Toyotas recently [marketwatch.com]? Remember all the hype about t

You are right. BTW, I don't doubt that China is building cyberwarfare capabilities for attacks to disable important pieces of infrastrcture. There is too much evidence at the moment to discount that. Also to an outsider, this sort of thing looks bad.

However, all this being said.... This sort of paper is not a threat. If you want to use an attack, the thing you don't do is alert the target to the vulnerability beforehand so that it can be corrected.

If you want to build a power grid in country X right now, take a look at the vendors that supply the products. Then take a look a the vendors that supplied the products 10 or 20 years ago. The same dozen or so of vendors supply all the equipment from control room automation to the actual hardware to make and distribute power to everybody everywhere in the world.If the US power grid can be hacked then so can most other power grids because you will find the same equipment and software over and over again.It's a bit like the good old MAD during the cold war: sure you can hack my power grid, but I can also hack yours...

All power grids are always vulnerable to physical attack. There are few generation stations, relative to the number of customers and many large scale distribution lines. Take those out, and you've disabled power for a long time since they have to be rebuilt. A big, distributed, power grid like we have that does not have tons of excess capacity is just going to be at risk of having large parts taken off line by physical means. Ask anyone who lives in an area of heavy snow.

Now, I understand that an electronic attack could be done remotely, in theory without warning. Ok... To what end? In case people haven't noticed there's a big ole' swath of ocean between the US and China. So if China was to try that as a precursor at an attack, it wouldn't do any good. We'd either already know about the attack, having seen the ships on the way, or it would be way too early, since the ships would take a long time to get here, and it would be back up by the time they got here.

Not that any of that is very relevant to defense. It isn't like aircraft carriers are on the power grid, they've got their own nuclear reactors (2-4 of them in fact). You discover a good deal of important stuff has its own power backup since it isn't like power doesn't go out all the time anyhow. Hell we lose power to our building at work probalby 3-4 times per year, hence there's a generator on critical systems.

I just don't see how this sort of thing is that big a deal. Now please understand, I'm not saying we shouldn't try to secure it. When you find a security hole, you should fix it. Just a good idea over all so you don't have problems in the future. However I don't see it as being a military threat. I see it as being more of a script kiddie type of threat. Some asshole takes power out because they think it is funny. I don't see China trying to knock it out because I can't see how it would be useful, and it would have some rather large negative repercussions if they did and the US found out who was responsible.

It is a big deal because, timed correctly, you can cascade a failure and shut down a huge chunk of the grid. Maybe your building has a generator for critical systems, and it can run for 72 hours on its propane tank.

But can the next shift show up, if the trains aren't running? Traffic control is down?

How many hours can you last, with no food and possibly limited and no water? So your server room is running; who is there to man it?

Just talk to the people who weathered Andrew, Hugo and such. Having your own power backup does little good if you also don't have all of the people there to put it to use.

Anyway, this is clearly not a threat. It's a vulnerability, and should be addressed.

OTOH, the intelligence community has a different definition of "threat" from most people. A "threat" is what your opponent *could* do, not what they *intend* to do.

So the intelligence people analyze "threats" from Canada, UK, etc. Certainly UK or Canada are "threats" in that they have the location and/or the military might to cause the US significant damage. It has nothing to do with their "intent"; that's for the politicos to decide.

So if China was to try that as a precursor at an attack, it wouldn't do any good. We'd either already know about the attack, having seen the ships on the way, or it would be way too early, since the ships would take a long time to get here, and it would be back up by the time they got here.

Suppose China disabled the USA's electrical grid via physical attack. There would chaos - transportation shuts down, cities run out of food, medicine, etc. China then sends large scale military force over as a "peace

Taking out the physical generation stations is actually expensive and difficult. The hard-on factor in a cyber attack is that it theoretically can be executed very cheaply. The US has spent a great deal on defense and would hate to see it bypassed by some sixteen year old with a CoCo2.

I wouldn't say that much, all current systems yes, but ones that could be implemented in the near future definitely not. The weak spot in the equation is the centralized nature of things. Just like how FTP servers are easy to shutter to stop the source of pirated content relative to torrents that allow many to be involved.

As solar becomes more prevalent, the power grid could be altered to more closely resemble the fishnet that became the internet. You'd have many smaller sources closer to where people us

Assymetric warfare. The Chinese have little intention of attacking us openly, physically. Their conventional warfare forces are being developed more to deter us from attacking for revenge, than to be used against us.

Pretty damned good find. You deserve a mod point or two, just for taking my post seriously enough to look!;^)

As the article makes obvious, no one in Washington takes the concept seriously. So, WTF are they doing in Washington? Send them all packing, I say.

The article falls a little short, though. There was a quote from some insider or another in the Chinese government, which defined the Assassin's Mace better. Their plan is, dominating us politically, economically, militarily, AND technologically, wit

Project Manhattan was a desperate gamble in the middle of the war, with the added benefit that America wasn't being bombed on its own soil like Germany was.

We might also note that the US and UK were bombing Germany's research sites, and especially targeted facilities that dealt with things like isotope separation and heavy water. Roosevelt's administration was actively trying to prevent German development of the atomic bomb. It was a lot harder for the Germans to target American research sites.

China doesn't have the capability to attack the US militarily but it can cause a significant amount of damage by attacking the US economy and promoting anarchy amongst the US population. The bonus is the possibility of carrying out this attack anonymously. Once the electrical grid is down, not only does the US economy take a hit but people start rioting and looting. The police and military would crack down on its own population and start fueling rage directed towards the authorities. Instead of everybody co

...to property they're going to legitimately own, thanks to the much slicker trick of rigging their currency exchange rate?

Well, just think of yourself as a caretaker. Hell, if you bought a house you don't really own it, not when your local government can and will take it away from you an instant if you don't pay your taxes. The essence of ownership is control, and we've already given that up to our own governments, and it looks like we'll eventually have to give it to China.

I guess the profile of the Chinese being ultra-patriotic and always acting in the best interest of China, together with the nagging (alleged) cyber-sleuthing on US networks makes this behavior understandable, but he's overreacting. However, the situation Wortzel described could have been real, and there's no way for him to judge. The alert seems to have been canceled already, so problem solved. No black helicopters with identity-less elite commandos arriving in the night to slit the throat of an innocent ge

You say "there no way for [Wortzel] to judge" the situation. Which seems untrue, unless you are saying that Wortzel is unqualified to discuss or provide analysis of this type of research. He certainly could of looked at the Journal itself and seen what else was in there. He certainly could have talked to others non-Chinese researchers BEFORE talking to Congress.

The fact that the article was in a Journal and published say in a Taliban newsletter should have been at least a starting point; not a point to jump

I think anything is possible.. and there there is always the possibility of just being lazy... but I think the net result of this is more hostility between the US and China; even though it's been "cleared up" there is sorta of a harmonic effect that the idea that the Chinese are attacking the US power grid is out there... perhaps some benefit from that increase in hostility.

I really can't understand this way of thinking. It will probably get me modded down but I ask of you to think about this.
What are you afraid of? every time I turn on the tv I see news from the US and every time it is about being scared or about why you should be scared and every time it turns out to be a lie.
Why do you feel threatened by a person who is not born in the USA who tells you there is a flaw in your system and goes so far to even tell you all about that flaw.... I don't get it. I just don't get in, I'm sorry.

Mr. Wang’s work was a conventional technical exercise that in no way could be used to take down a power grid.

no practical scenarios of an attack on the real power grid can be derived from such work.

From what it sounds like the entire article is about him overreacting to a nonspecific, and in this case completely unworkable white paper. The news here is not that the US is vulnerable but that the people in charge of securing it are a little quick to fire off against anyone who undermines them even if they didn't.

I suspect this is about the military definition of threats.(Warning: I've worn that particular hat, as a former MI assigned officer in an S2 shop for a cavalry regiment. I've never been a politician, so what you're getting here is definitely only one side of the argument).
The way Military Intelligence is supposed to work, reports consider capabilities, but they deliberately don't consider intentions. MI is never in command and NEVER makes command decisions, but reports to commanders, or at higher levels, to civilian overseers.
For example, an high ranking Army Intelligence officer might be supposed to give the US Congress a good answer to whether country X has missiles with enough range to reach the US. He or she can't give a good answer, and so shouldn't comment, on whether country x has intentions to use them on the US or on someone else (at least unless there's a real obvious 'smoking gun', like the officer has found a copy of the orders where all the missiles are suddenly being retargeted at country Y and the job has to be completed by 1300 hours when "Operation Obliterate Country Y" begins).
It's up to civilian oversight to determine whether a threat (potential) becomes an enemy (actual). The military is not supposed to decide when to go to war, that's the job of civilians. If you want congress or the president to be the ones to decide whether the US needs to go to war or not, you can't have the pentagon declaring in advance who is an enemy and who isn't.
Right now, Great Britain has pretty serious threat potential (They have weapons which could damage the US, and ways to transport them to us). They don't suddenly count as an enemy just because of that. Pakistan has less threat potential (not as many weapons or delivery systems). Imagine a coup puts militant Taliban related forces in charge of Pakistan's nuclear weapons. They might suddenly be classed as an enemy nation, but what happened to the threat assessment? Nothing! They are exactly the same threat, from a Military Intelligence assessment, as before. Same number of bombs and missiles and troops, same threat.
Put that way, a person who can figure out a good way to attack the US is a threat, or a small part of a threat. That he's shared his info with us should make the civilians who are supposed to decide what actions to take figure he's not an enemy, and that any potential threat here is not likely to become an actualized attack. Common sense tells normally rational people that if this person was part of a secret plan that would eventually use his information against us, he wouldn't have mentioned it all publicly. The people he was connected to in China would be unknown to us, not publicly accessible, and so on. But that means any intelligence system which discovered threat potential here probably reported it right, it's just civilian overseers acted like paranoid fools.
For another analogy. Let's say you have two people nearby who can both lift over 300 pounds. They both represent similar threats to you, in the most technical sense. One is there to help you move your furniture, the other is an escaped convict looking for a hiding place. Only one of them is at all likely to attempt to harm you, and it's quite possible he has no intentions against you either. You might classify the mover as an ally, and then it's a judgement call if the convict is an enemy at that point, but both technically have near identical threat potential from what you know. This whole matter sounds like a case where someone is conflating the facts and the conjectures, to try and make people be equally worried about 'moving men' and 'escaped convicts', and then assume the worst possible scenarios are inevitable and not just possible for the convicts as well.

The issue of vulnerable power grid is a legitimate threat, but the individual creating a study about it is not. You get it backwards when you say the individual is a threat and paper (or the vulnerability) might be harmless. A grad student won't have capability or interest in taking down US power grid, instances with capability to harm US power grid have also means to create similar study on their own. I'm sure even US military has created similar study and have planned on supplying electricity to critical locations without the electric grid.

There are many valid reasons why US electric grid was chosen to be target of the study. Creating similar risk analysis on Chinese electric grid could be a serious offense in China, or information about US electric grid was more available than any other major electric grid in the world. Most likely this student has interest in working at the electric grids and wants to help to build one that is more secure.

From the liberal in the 1950s branded as a commie pinko, to the19 year old with a 15 year old girlfriend branded as a pedophile, to theCasual torrent downloader branded as the biggest threat to Hollywood ever, to theSecurity researcher branded as an enemy of the state,

we all suffer when people are scapegoated so someone can get his time in front of a microphone.

Would someone please dig up J. Edgar Hoover's body and make sure he's still dead? Methinks his ghost never left us.

Way to miss the point. I don't buy that crap either - I'm an atheist. However everyone has lied, or stolen something, or done something illegal at SOME point in their life. EVERYONE. The day that "authority" is capable of strictly enforcing the law on everyone everywhere and at all times is the day we lose our humanity and truly become nothing but disposable cogs in society's machinery. Because sooner or later everyone can and will be rounded up, it wi

Public security research is not a threat. Vulnerable infrastructures that go unchecked are.
The trend is to penalize security researchers for publishing their findings will only increase underground security research that will then just be sold to the highest bidder.

"Responsible disclosure" is a concept dreamed up by vendors to allow them to stall and procrastinate when it comes to fixing bugs as long as possible. The only "responsible" disclosure is full disclosure.

Public security research is not a threat. Vulnerable infrastructures that go unchecked are. The trend is to penalize security researchers for publishing their findings will only increase underground security research that will then just be sold to the highest bidder.

Public security research is a threat. But it's not the researcher's fault; It's the people who wait for research like this to be published and then use it (open source intelligence gathering) to develop attacks. It's easier to target and blame the researcher for publication than to attempt to find the malignant factors, who are increasingly operating independently and lack connections to an organization. Which means, in short, they're operating under the radar. Conventional intelligence-gathering efforts depend on the fact that as the number of criminals cooperating increases, the chance of mistakes being made which expose them increase exponentially. Also, the number of communication channels between people increase geometrically, resulting in a larger signals intelligence footprint.

So basically, it's cheaper, even if it's not ethical. And ethics, as you know, are decided by those in power. So there will always be a rationalization to discredit and imprison people who come forward with security problems, simply because it's cheaper to do so than fix the underlying problems, which they are already well aware of and would prefer you not tell them that the emperor has no clothes.

Unfortunately, the logical conclusion for this kind of reactionary thinking is that eventually a backlash will build up and people will begin independently engaging in small-scale acts of sabotage in an attempt to bring attention to these problems (which has recently started to happen domestically). The government's over-reaction to these attempts by the citizens to excercise the only recourse left to them by creating harsher penalties, more survillance, and secret courts, will eventually result in larger targets being attacked and destroyed, by independent citizens or small groups.

We've been here before -- in the late 1800s, in the 1960s and 70s, and briefly again in the late 90s. It's cyclical. The problem is, each time it happens, it gets worse, and the government refuses to acknowledge this systemic failure of its domestic intelligence policies. Eventually, we're going to have another 9/11, but we won't be able to blame anyone but ourselves when angry citizens start taking out government buildings.

And the reason is we've left them with no alternative: Terrorism is, in fact, a valid way of promoting change when all other methods have failed. The strength of a democracy is the fact that we have all those other methods open to us. Close them off, like we're doing now by punishing people who have knowledge and publicly state the failings of the system and draw attention to needed repairs... And it will come to our own soil with a vengance. And we'll have nobody to blame but our ill-designed domestic policies for it.

Perhaps the intelligence community needs a better way of accepting reports of these problems and rewarding citizens for being diligent, instead of imprisoning them and invading their privacy as potential subversives. And perhaps expanding the definition of citizen to include anyone who works to secure our future, domestically or internationally. How about the concept of honorary citizen? These are the principles and actions we should be striving for -- not this goddamned police state bullshit.

Both are filled with more quackery than actual sound practices. There is very little difference between most "security experts" today and the snake oil peddlers who told the public that their 150 proof secret tonic could cure everything from whooping cough to "consumption."

The U.S. is reactive and not proactive. The U.S. always has to wait until after the fact to admit that there was a threat. This is nothing new to me. Just read Unrestricted Warfare [c4i.org]. The Chinese have been stating this for years now. Yes everything will be fine until the lights go out.

Wow.
As a European I must say, we have a different truth... The us reactive? I am very sorry, maybe in the US you think that, but I think the general public opinion about the US - worldwide - will think otherwise... Don't mean to offend you, just here to inform you:)

No, you don't offend me. I see where you are coming from due to our "over reactive responses" to 9/11. What I am talking about is taking more proactive measures. Perhaps 9/11 could have been avoided have we had a different foreign policy, didn't arm extremists with the short sight that in the future there could be blow back, and last but not least ignore all the guys taking flying lessons that didn't want to learn how to land the aircraft.

Net to me the problem is, that such a comment is from an AC... I'm sure you have a real account here. Use it. I said something I knew was going to offend people, although I feel they should not be offended, but I don't use the AC option;)
But just that kind of behavior, is what is upsetting people about the US. It's true...

Well, to be honest, I think the US is very pro-active and when I am absolutely honest.... I even think that the invasion of Iraq has nothing to do with 9/11 but all with the former presidents personal cashflow. Now and in the future. I'm pretty sure he will die a wealthy man but I am not sure at all about the 'bring peace' part of his speech back in those days.

I got interested and read a few passages. I am convinced it is a forgery, and of bad quality at that. One hilarious passage read:

[...] Bill Gates opens new "Windows" each year, and "Dolly," the cloned sheep, proves that mankind is now planning to take the place of God the Creator.

Only a conservative Christian could write such a passage. A PLA colonel would avoid religious references entirely, and surely would not write about a single creating entity. There is some material on W

It's a cultivated and educated effort at fear mongering, which is consistent with the U.S. indoctrinal system which has been in place, and under refinement, since the end of world war II. The analyst in question has this say about himself:

Dr.Dr. Larry M. Wortzel is president of Asia Strategies and Risks, LLC. He provides consulting services on defenses, security, political and economic issues related to China and East Asia.
Wortzel has 37 years of experience assessing events and working in the Asia-Pacific region. He is the author of two books on China’s politics and military affairs. In addition, he has edited and contributed chapters to eight other books on China’s military forces. Wortzel has lectured in and contributed his expertise to newspapers, magazines and government officials in China, Taiwan, South Korea, Japan, the Philippines, Malaysia, and Thailand. During a 32-year military career he served in China, South Korea, Singapore, and Thailand. Wortzel has been a strategist for the Pentagon and was director of the Strategic Studies Institute of the U.S. Army War College. He was vice president for foreign policy and defense studies at The Heritage Foundation, a Washington, DC, think tank. He is a commissioner on the Congressionally-appointed US-China Economic and Security Review Commission.

(from his webpage)

The guy is a member and servant of the circle of elites who profit, and enjoy enormous social success from their support of our militarized social and economic system. Pursuading a population of relatively free and relatively educated person to support an political system which can afford to spend $3 trillion dollars (washington post estimate) [washingtonpost.com] on an injust, unjustified terrorist war against an impoverished nation, against a dictator we incidentally empowered and supported through the worst of his crimes, and over the objections of its own citizenry, but quails at spending $1 trillion to ensure health care said citizens.

Wortzel enjoys a position of prestige and wealth for his support of the forces of that are destroying us, as do the reporters and editors of the New York Times for parading his observations without the criticism they deserve.

For anyone with a certain amount of research background, or even basic knowledge of network security and stability issues (in this case network in question is power network), the appropriate response to the paper would be analysis, and investigation and applicatoin of measures to improve the stability. The U.S. power grid has in recent years suffered from such cascading network failures several times in the last decade, and we Americans should be grateful that someone is investing the resources to investigate these issues. By publishing his results in a peer reviewed scientific journal, Mr. Wang has done us a service, and deserves our gratitude. Instead he's getting caught up in this policy wonk's latest search for enemies.

When it comes to really big organizations, something like security does not exist. Social engineering and insider knowledge (which is not something to be kept secret) is usually enough to have a certain chance of convincing some moderately qualified person to assist you somehow in attacking some system. Unless you are really restrictive about communication to the outside, like no phone connections to the public phone network, only internal e-mail for all normal employees below a certain level. I would appre

other than our lower middle class buying all there cheap crap at various discount retailers (i.e. Wal-Mart,Target, you fill in the blank). If they wanted to do any real damage to us they would simply quit buying our debt but then who would buy as much of their cheap junk as dumb lower middle class Americans do!?! Not to mention that if they really wanted to do some damage they could quit buying our debt and quit selling us cheap junk then our country would collapse. We simply do not have the manufacturing a

It's a worry. Power grids use the Internet extensively. Since "deregulation", generating companies and distribution companies are separate businesses, and the generating companies compete with each other. The generating companies make bids, the distribution companies buy from the bids, and the grid operator (a neutral party) keeps the players connected and runs the market. Bear in mind that these systems don't have much excess generating capacity. 12-20% excess capacity during peak periods is typical. For a good overview of how this works, see Background on Generation Control [acrobat.com], an online training course from PJM, the biggest grid operator in the world.

Most of the communication between the various players takes place over the Internet. The bid handling is done on machines connected to the Internet and many of the applications involved are Windows-based. The execution of a power buy involves the transfer of a set of switching decisions from the bid-handling machines to the machines which actually have control over generation and transmission equipment.

If the Internet-based apps go down, they revert to "conservative operation" and stop trying to optimize the economics. All generation facilities, even high cost peaking plants, crank up to at least standby power levels, in case they're needed. Export of power to outside the control area in trouble is stopped.
Coordination is over the "all call", a squawk box system, and satellite phones. Worst case, everybody backs down to a preplanned schedule of what they're supposed to be doing at each hour of the day. In this mode, millions of dollars per hour are being lost, but the grid can probably be kept up.

One worry is insertion of bad data into the bid system via the Internet. The California ISO had outages in the early part of the last decade when energy traders put bids into the system which resulted in transmission congestion, forcing the CAISO to buy more expensive power. Back then, California had an energy auction every half hour. That was an extreme of deregulation. Now, the grid manager has more authority; generating companies put up data which offers price/quantity curves as bids, the grid operator takes them in increasing order of cost, and "energy traders" like Enron are no longer involved in hour by hour decisions. So there's more stability in the system.

Internet-based attacks against the control systems are also a worry. There definitely are connections to the external Internet. PJM seems to be using XML, in well-defined formats, to pass data across that boundary. They're not dumb. The problem is making sure that there aren't unwanted connections somewhere amongst the hundreds of different companies which connect to the control side of the system.

It's interesting that PJM doesn't rely on "security through obscurity". Hundreds of thousands of people have to know how this works. So they put the manuals, training materials, and live operational data [pjm.com] on the Internet. (Right now, there's a problem near the West Virgina/Ohio border.)

I must not fear.Fear is the mind-killer.Fear is the little-death that brings total obliteration.I will face my fear.I will permit it to pass over me and through me.And when it has gone past I will turn the inner eye to see its path.Where the fear has gone there will be nothing.Only I will remain

God that movie was hideous. The book is a Sci-Fi classic, and there is a mini-series that did it much much better. Please use either of those as your reference instead of the god-awful 80's movie. I love Patrick Stewart as much as anybody, but even he couldn't make up for that movie. It was just all wrong.

Look, I know it's easy for people to think he's planning an "attack", but I think he's just trying to be proactive.

Being Chinese, he no doubt craves video games, online MMORPGs and anime to a level that a Westerner just can't understand. Just put yourself in his shoes for a moment. Could you really go 30 minutes, or maybe even an hour, without playing some Wii or playing WoW or seeing some tentacle rape? No, you probably couldn't. So you'd do everything you possibly can to ensure that you have electricity 1

I would say that it's not only the US power grid that's vulnerable. It's power grids and users all over the world that are vulnerable to threats.

Large exposure - often in inaccessible terrain.

Key points in rural areas with little protection.

Very visible installations makes them easy to map.

Number of persons knowing the large scale circuits in their head are few.

Societies highly dependent on electrical power.

Availability of material (especially large transformers) and competence for repairs of major lines are limited.

Alternate routes may already be running at maximum capacity.

So I would say that the report hardly surprises me. Coordinated attacks on power lines in areas hard to access in a part of a country and then a follow up with some anti-aircraft weapons to take down the maintenance helicopters and you have a big problem. Take out a number of transformers and you can really sit back and see that those oddballs insisting on collecting firewood are the survivors while the rest are running around in circles. Especially tough in the middle of the winter.

Secondary effects of a prolonged power outage would be telecom breakdowns, water and sewage plant failures, failure to get fuels for vehicles etc. Those are just the direct and obvious effects. The economy would be taking a major hit at the same time.

Just figure out if there were a coordinated attack that cut off electricity to many major cities at the same time. It would make what happened in New Orleans when Katrina had struck just an exercise.

"Take out a number of transformers and you can really sit back and see that those oddballs insisting on collecting firewood are the survivors while the rest are running around in circles. Especially tough in the middle of the winter."

This is going to derail the discussion massively, but I read a neat article recently which pointed out that survivalists, preparers etc are sort of missing the bigger picture. If the world goes to hell in a handcart and you're the one sitting pretty on a two hundred year supply

I hope the Chinese haven't watched that old Twilight Zone episode The Monsters are Due on Maple Street [wikipedia.org]. I guess the episode isn't so much about people attacking those who have supplies as much as people attacking those they are suspicious of, but whatever gets the job done, huh?

Our family farm is just outside the tank-of-gas-plus-how-far-'til-the-blisters-cripple-the-flatlanders range of the major cities. Pop's hoping for the National Guard to secure the pass over the mountains. If not, we are prepared to repel boarders as well. I've seen angry mobs before, and I'm pretty confident they will stop each other pretty much right where they coast to a stop. What did we overlook?

A lovely sentiment, to be sure; I take it you weren't in Los Angeles in April of '92. I would be saying that myself if I hadn't personally observed the shmoogs, unleashed. I will likely be helping some of my fellow human beings, to a point. I am not a "Christian" and I feel strongly disinclined to draw that line anywhere near to the risk zone. Refugees are welcome to pass by, (preferably out of range), and try their luck in town, but I imagine they'll be as welcome as the Joads. Too bad,so sad.

Just figure out if there were a coordinated attack that cut off electricity to many major cities at the same time. It would make what happened in New Orleans when Katrina had struck just an exercise.

There is a pretty good template here at Northeast Blackout of 2003 [wikipedia.org] on how to take out power to 55 million people; just substitute shot-out high-tension insulators for power-line tree contact. It easy to dog on authorities for being over-zealous but when you compare "what has been done" to "what could be done" multiplied by " how many whack-jobs would like to do it" it's hard to blame them.

I was thinking more along the lines of "effing great, kill the messenger".

Here's your "enemy" telling you where a critical resource of yours can be attacked. This alone is a boon, not a threat. Assess his attack vector and there are two possible reactions: Either you notice that he is wrong and you keep it at that, hoping that your enemy will believe that this is a feasible way to attack you. When they do, it fails but gives you a the psychologic and diplomatic upper hand. Or he is right and you should get

Actually, I am American, and I love America - enough to have served her armed forces for 8 years, and to raise both a soldier and a sailor. But, I agree with AC. WTF is it with torture? Torture was almost universally condemned throughout the western world, until Herr Shrub came along. FFS, any competent intelligence officer will tell you right out, he can get better results by buddying up to a suspect, rather than torturing him. Offer the guy a cigarette, a beer, ask about his wife and kids, tell him how beautiful his wife and daughters are (even if they are Sumo heavy weights whose faces have been used for dart boards) - sugar catches more flies than vinegar ever did.

I am not only American and love America, I have (almost) always voted Republican.

Gitmo needs to be closed as a detention facility. I'm not even sure it needs to exist as a naval base, but that's a different issue.

The "detainees" are either criminals or they are prisoners of war.

We have rules for dealing with both. A determination needs to be made, one by one, in an expedited manner, which is which, and those rules followed.

If we can't assign a person to either group then maybe they should be released wherever they were captured, with a change of clothes and an apology for the water boarding and genital chewing.

The fact that we are apparently incapable of doing so and would rather continue the water boarding and genital chewing is an embarrassment.

Instead, if the Chicago Tribune is to be believed, we're going to start sending them to Bagram (Afghanistan) instead. (Today's paper, section 1, page 25.)

The whole point of "closing Gitmo" is supposed to be to do the right thing - not to do the wrong thing again, just somewhere else. Some quotes:

But without a location outside the U.S. for sending prisoners, the administration must resort to turning terrorism suspects over to foreign governments, bringing them to U.S. soil, or killing them.

U.S. officials find those options unappealing for handling suspects they want to question but lack the evidence to prosecute. For such suspects, a facility like Bagram is necessary, officials said."

...terrorism suspects held inside the U.S. would likely have the right to challenge their detention in federal courts. Bagram, for now, is outside the reach of U.S. courts.

From my perspective, that is kind of the point. If the U.S. government is holding someone, that person should have access to U.S. courts, or they should be subject to the Geneva Convention rules. Period.

This kind of behavior is not what the United States is supposed to stand for - it isn't even what we are supposed to tolerate in other countries.

Do I read that right? If they haven't been found guilty of anything, they are automatically prisoners of war? Thank goodness nobody innocent ever got locked up!

I think the point was that the detainees are either accused of criminal activity or prisoners of war. The government needs to make the call on each individual and treat them to the laws that govern handling of accused criminals or prisoners of war.

Vinegar is extremely effective at catching flies because it smells like rotting fruit (that's basically what it is, actually). Flies love rotting fruit a hell of a lot more than they like fresh fruit, in case you haven't noticed.

The classic trap is to fill a jar with vinegar and attach a funnel just large enough for the flies to get in but small enough to make it difficult to get out - the hole can be several times the size of the fly and still ac

Larry M. Wortzel "overreacts" because he needs something to justify his job, his pay, and this will get him some attention which could lead to bigger and better things.

Indeed. And fixing the problem here can't be done by attacking him and others who take the approach of "Shoot the messenger" in cases like this. It might be fairly obvious to a lot of us that we want people finding such problems and telling us about them. The alternative is that we don't hear about a problem until someone exploits it. But